For all the hype over how many people downloaded Mozilla’s Firefox 3 open-source browser in a five-hour period, there is now hype about how long it took security researchers to disclose a flaw.
Five hours after Mozilla officially released the much-anticipated update, Tipping Point confirmed a vulnerability. Tipping Point’s Zero Day Initiative program received notification about a critical vulnerability affecting both Firefox 3 and Firefox 2.
“We verified the vulnerability in our lab, acquired it from the researcher, then promptly reported the vulnerability to the Mozilla security team shortly after,” Tipping Point wrote in its Digital Vaccine Laboratories blog.
“Successful exploitation of the vulnerability could allow an attacker to execute arbitrary code,” the company said. “Not unlike most browser-based vulnerabilities that we see these days, user interaction is required, such as clicking on a link in e-mail or visiting a malicious Web page.”
Take All Normal Precautions
Mozilla is working on a fix, and Tipping Point isn’t saying much else until a patch is available. So just how serious is the threat? It’s difficult to say for sure, according to Carole Theriault, a security researcher at Sophos, because there’s not much detailed information on the threat.
However, she said, it would be sensible to take the normal precautions that people are advised to take: Visit only reputable Web sites, patch security vulnerabilities, and put this patch in place as soon as Mozilla makes it available.
“Companies that are concerned that their users are dashing out and installing the new browser should consider controlling what browser and version can be used in the company,” Theriault said. Tools like Sophos’ Application Control allow administrators to control browser usage within the network, ensuring that the network is not at unnecessary risk.
Was Mozilla Set Up?
It’s not unusual for bug reports to emerge in the wake of newly released software, especially…